Remove global ATS exception and document Keychain-backed secrets - #1
Open
forbesfields wants to merge 3 commits into
Open
forbesfields wants to merge 3 commits into
forbesfields wants to merge 3 commits into
Conversation
- Drop NSAllowsArbitraryLoads from project.yml and Info.plist; custom provider endpoints are validated at save time in CoderSwitchCore (https required off-loopback). - SECURITY.md: Secret Handling and Known Hardening Items now reflect the Keychain-backed SecretBox root key, Keychain proxy admin key, OAuth state validation, and loopback-only callback listener. Pairs with the coderswitch-studio core PR (secret migration, OAuth state/callback hardening, endpoint validation, migration tests).
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
UI-side half of the security-hardening pair; core changes are in coderswitch-studio#1.
Changes
NSAllowsArbitraryLoadsfromproject.ymland the generatedInfo.plist. Custom provider endpoints are now validated at save time in the core package (https://required for non-loopback hosts; loopbackhttp://allowed; no embedded credentials). Upstream forwarding to non-loopback plain HTTP therefore fails closed, while loopback local-development endpoints keep working (ATS exempts loopback by default).SecretBoxroot key with automatic.master.keymigration, Keychain proxy admin key, OAuthstatevalidation, loopback-only callback listener — and what remains (Google client secret rotation, sandbox decision, post-migration key rotation).xcodegen generate; verified withplutil -lintand confirmed the built app bundle contains noNSAppTransportSecuritykey.Verification
xcodebuild -scheme CoderSwitch -configuration Debug build: BUILD SUCCEEDEDInfo.plist: noNSAppTransportSecurityentryswift testincoderswitch-studio/Packages/CoderSwitchCore): 81 passed, 0 failures/healthz→{"ok":true}, unauthorized/v1/models→ 401Notes
README.mdhas unrelated uncommitted edits (not part of this PR, left in the working tree).PROGRESS.mdis gitignored; the changelog entry for this hardening work was updated locally.